September 24, 2026
Card testing fraud is when someone uses stolen card numbers, expiry dates, and CVVs to run small transactions through a checkout, purely to confirm which cards are still valid. It relies on the same legitimate payment rails every honest customer uses, which is part of what makes it hard to catch early.
If you're asking what card testing fraud is in plain terms, think of it as a filter. Fraudsters rarely acquire clean, verified card lists. Instead, they buy or trade raw batches of stolen numbers, often mixed with cards that have already expired or been reported stolen. Running each number through a live checkout sorts the working cards from the dead ones.
Fraudsters usually source this stolen data from data breaches, phishing campaigns, or dark web marketplaces. A payment platform with light verification, like a donation page or a low-cost subscription signup, gives them exactly what they need to run that sorting process undetected.
Once a card passes the test, its value jumps. The fraudster can use it directly for a larger purchase, or sell the verified details on criminal forums for a premium. Card testing fraud is rarely the final goal; it is the reconnaissance step that makes every later fraud attempt more efficient.
A typical card testing fraud attack moves through a short, repeatable sequence:
Fraudsters buy or trade lists of stolen card numbers, sourced from breaches, skimming devices, or phishing pages, often in batches of hundreds or thousands.
These lists are commonly traded on dark web forums, where sellers bundle card numbers with partial cardholder details to make them more attractive to buyers.
The fraudster, or a script acting on their behalf, submits low-value charges, frequently under a dollar, against a merchant's checkout.
Digital goods, donation pages, and subscription trials are common targets because they process high volumes of small transactions already, which helps the test blend in with legitimate traffic instead of standing out.
An approved transaction confirms the card is active. Even a decline can leak information; a decline for insufficient funds tells the fraudster the card is real, while a decline for an invalid card number tells them to move on.
Sophisticated fraudsters track these codes closely, since they reveal almost as much as an approval does.
Cards that pass get flagged as verified. Cards that fail get discarded.
This sorting step is what makes credit card testing fraud so efficient at scale, since a single script can clear thousands of numbers in minutes and hand the fraudster a clean, working list to act on.
The fraudster either makes a larger purchase directly or sells the verified card list, which fetches a higher price than an unverified one since the buyer knows it works.
Verified lists routinely change hands multiple times before the card is ever used for a large purchase. This is also why card testing fraud is so hard to trace back to its source.
The actual damage, a large fraudulent purchase or a wave of chargebacks, often shows up weeks or months later at a completely different merchant than the one where the testing happened.
Credit card testing fraud is not a fringe problem. In the first three quarters of 2025 alone, more than 500,000 cases of credit card fraud were reported to the Federal Trade Commission, nearly 180,000 more than the same period the year before. Card testing sits behind a meaningful share of that volume, since it's the entry point for so much of the fraud that follows.
The financial scale keeps climbing too. Global card fraud losses are projected to reach 41.06 billion dollars by 2030, and eCommerce fraud is expected to grow from 44.3 billion dollars in 2024 to 107 billion dollars by 2029, a 141% increase. Another research found that nearly 90 percent of businesses lost up to 9 percent of revenue to fraud in a single year.
None of this happens because merchants are careless. Card testing fraud looks like ordinary low-value traffic, and automated tools let a single fraud ring run thousands of test transactions across dozens of merchants in the time it takes an analyst to review one flagged case.
That mismatch in speed is exactly why credit card testing fraud keeps growing even as awareness of it does too.
Not every card testing fraud attempt looks the same, and the method usually determines how fast it moves and how visible it is.
Here are some common types of card testing attacks people usually face:
A fraudster tries a small number of cards by hand, adjusting details based on the decline codes they get back.
It is slow and low-volume, but it still produces a signal, usually a handful of small charges or declines from the same customer profile within a short window.
Manual testing is more common with smaller-scale operators who bought or stole a limited number of cards and want to avoid the visibility that a large automated run would create.
Bots submit card and CVV combinations at high speed, sometimes thousands of attempts in a few minutes.
This is the more damaging version of card testing fraud, since a single automated run can validate an entire stolen card list before a merchant's team even notices the spike.
Enumeration attacks often rotate through proxy networks and residential IP addresses specifically to avoid triggering simple IP-based rate limits, which is why device and behavioral signals matter more than IP address alone.
Instead of testing individual stolen cards, fraudsters use the bank identification number (the first six to eight digits of a card) and generate the remaining digits, expiry dates, and CVVs algorithmically.
A successful BIN attack can produce dozens of working card numbers from a single starting sequence, without the fraudster ever having stolen a real card in the first place.
This makes BIN attacks especially concerning, since they do not depend on a prior data breach at all.
Card cracking targets gift cards, prepaid cards, and store credit accounts rather than traditional credit or debit cards.
Fraudsters use similar enumeration techniques to guess valid card numbers and PINs, then drain any available balance before the legitimate owner notices.
Because gift card and prepaid systems often have lighter fraud controls than standard card networks, they tend to be an easier entry point for testing scripts to succeed on their first few attempts.
Recognizing credit card testing fraud early keeps a small problem from turning into a large one. Now that you know what card testing fraud is and why it happens, the challenge becomes knowing which patterns to watch for.
These are the signals worth watching for:
Now that we've covered what is card testing fraud and how it operates, it's worth spelling out exactly what it costs a business that gets targeted. Card testing fraud creates damage that goes well beyond the value of the test transactions themselves.
For a growing business, that kind of restriction can be far more damaging long-term than the fraud losses that triggered it in the first place.
Card testing fraud concentrates wherever checkout friction is low and transaction values are small.
Understanding which industries attract the most attempts helps a fraud team prioritize where to tighten controls first:
If your platform falls into any of these categories, it is worth assuming you are already a target rather than waiting for a visible spike in chargebacks to confirm it.
Card testing fraud tends to find the checkout flow with the least resistance, and it moves on the moment that flow gets harder to exploit.
Card testing fraud prevention works best as a layered system rather than a single control. Here is what an effective setup typically includes.
Pairing rules with a proper fraud detection setup that scores every transaction in real time, rather than relying on manual review after the fact, is what actually catches card testing fraud before it turns into a chargeback wave.
Understanding what card testing fraud is only useful if it changes how fast you act once you spot it. If you suspect an active card testing fraud attempt, speed matters more than perfection.
The goal is to contain the attack quickly without locking out legitimate customers who happen to share a payment pattern with the fraud.
Here’s a stepwise approach to help you respond effectively to a card testing attack:
Building your own card testing fraud prevention stack from individual point solutions works for a while, but most fraud teams eventually outgrow that approach as attack volume grows and false positives start eating into legitimate revenue.
If you are evaluating vendors instead, a few criteria separate genuinely effective tools from ones that just look good in a sales deck:
Many fraud tools train only on each customer's own transaction history, which means new merchants start with almost no protection while the model builds up experience.
A provider that pools data across a broader network of customers catches known bad actors and BIN patterns from day one, not after months of ramp-up.
This matters most for newer platforms that don't yet have years of their own transaction history to train a model on.
Card testing fraud plays out in seconds, not hours. A tool that only reviews transactions in nightly batches will always be a step behind an automated attack that clears thousands of cards in minutes.
Event-driven scoring that acts at the point of authorization is what actually stops a script mid-run, rather than just documenting the damage afterward.
Enterprise fraud platforms have historically taken 5 to 14 months to integrate, which is a long window to stay exposed.
Faster onboarding, measured in days or weeks rather than months, means protection starts working immediately instead of after a lengthy rollout.
For a business already under active attack, that difference alone can determine how much fraud gets through before the tool is even live.
A detection model that is too aggressive blocks legitimate low-value purchases and damages the checkout experience just as much as missed fraud damages your bottom line.
Ask vendors for real false decline numbers, not general claims, and find out how they tune sensitivity for your specific transaction mix rather than applying a one-size-fits-all threshold.
Card testing fraud prevention budgets are hard to plan around unpredictable fees.
Favor usage-based pricing with no setup costs over vendors that bury charges in multi-year contracts, since a transparent model also makes it easier to justify the investment to finance or leadership.
Ask for case studies with concrete numbers, such as fraud caught earlier than legacy tools or measurable efficiency gains for the fraud team, rather than a features list with no evidence behind it.
A vendor that can point to a specific, measurable outcome for a comparable customer is demonstrating something a generic feature comparison never can.
This is also where pairing card testing fraud prevention with a broader anti-money laundering platform matters, since verified stolen cards frequently feed into larger laundering operations further down the chain.
Catching the testing stage early cuts that pipeline off before it reaches that point.
Card testing fraud gets confused with a few related terms, and the distinctions matter for how you respond.
Here are some key comparisons you must know about:
Treating card testing as a standalone signal, rather than folding it into general chargeback monitoring, is what lets a fraud team catch a stolen card batch before it gets used for anything bigger.
This distinction also matters for how a business measures its own risk.
A merchant that only tracks confirmed chargebacks will consistently underestimate its exposure to card testing fraud, since most test transactions never generate a dispute at all; they simply confirm a card works and move on.
Tracking decline patterns and transaction velocity separately from chargeback rates gives a far more accurate picture of how often your checkout is being probed.
Now that you know what card testing fraud is – how it spreads, and what to look for, the next step is putting a system in place that catches it before it costs you.
Card testing fraud moves in seconds, which is exactly why siloed, batch-based tools keep missing it. Fraudio's AI-Powered Payment Fraud Detection scores every transaction in real time at the point of authorization, built on a centralized dataset that learns from billions of transactions across our network rather than just one customer's history. That means a BIN attack or bot-driven enumeration pattern seen at one merchant helps protect every other business on the platform from day one.
We deploy in 3-14 days, instead of the 5-14 months time-frame enterprise platforms typically take. The platform runs on transparent, pay-per-use pricing with no setup fees or long-term lock-in. This fits teams that cannot afford to wait months for protection while a card testing fraud campaign runs unnoticed against a new or growing checkout flow.
Book a call with our team to see how Fraudio performs against your own transaction data, with zero commitment required.
Card testing fraud is when someone uses stolen card numbers to run small transactions through a checkout, purely to confirm which cards are still active before using or selling the verified ones. The charges are usually under a dollar, sometimes just a few cents, to avoid drawing attention. It often serves as the first step before a larger fraudulent purchase happens elsewhere. Businesses that process high volumes of small transactions, like subscriptions or donations, are frequent targets.
Credit card testing fraud works by running stolen card details through a merchant's checkout and reading the response. An approved transaction confirms the card works, while even a decline can reveal useful information, since a decline for insufficient funds still confirms the card is real. Fraudsters do this manually in small batches or through automated bots that test thousands of cards in minutes. Once a card is verified, its value increases significantly on criminal marketplaces.
You can tell your business is being targeted by card testing fraud when you see a burst of small transactions, often under a dollar, arriving in quick succession from the same IP address or device. High decline rates, especially for invalid CVV or expiry date errors, are another strong signal. Mismatched billing details and unusual timing patterns, like evenly spaced attempts, round out the common warning signs. Newly launched checkout flows are especially common targets.
Effective card testing fraud prevention combines several layers rather than relying on one control. AVS and CVV checks catch a large share of basic attempts, while velocity limits stop scripts from clearing thousands of cards in one pass. CAPTCHAs filter out automated bots, and behavioral or device intelligence flags suspicious sessions even before a transaction completes. Machine learning scoring ties these signals together and adapts as new attack patterns emerge.
If a business ignores card testing fraud, the immediate cost is usually chargebacks and processing fees on the fraudulent transactions themselves. Over time, ignoring the pattern lets fraudsters verify larger stolen card batches against your checkout, increasing the odds of a bigger fraudulent purchase later. Processors and card networks can also flag the merchant account for elevated scrutiny, leading to higher fees or restricted processing. Left unresolved, repeated incidents can damage customer trust and revenue.
Yes, card testing fraud specifically relies on small transaction amounts, often under a dollar, because low-value charges are less likely to trigger a cardholder's attention or a bank's fraud alerts. Fraudsters deliberately choose amounts small enough to stay under most default fraud thresholds. This is exactly why relying only on dollar-value triggers for fraud review misses most card testing activity. Volume and velocity, not transaction size, are the more reliable signals to monitor.
Card testing fraud is not the same as a data breach, though the two are closely connected. A data breach is how fraudsters typically obtain the stolen card numbers in the first place, while card testing fraud is the separate step of verifying which of those stolen numbers still work. A business can experience a card testing attack without ever having breached itself, since the stolen cards usually came from an entirely different source.
Not when you consider what it enables. Card testing fraud transactions are intentionally small, but they are the reconnaissance step for larger fraud that often lands at a different merchant weeks later. Ignoring small-value test charges also leaves the door open for automated bots to clear thousands of cards through your checkout, generating disproportionate chargeback and processing costs relative to the value of the test transactions themselves.
How about trying our solution and experiencing the next generation for yourself?